CVE-2023-28081 is a critical use-after-free vulnerability (CWE-416) in Facebook Hermes versions prior to commit e6ed9c1a4b02dc219de1648f44cd808a56171b81, stemming from a bytecode optimization bug. This flaw allows for arbitrary code execution through a specially crafted JavaScript payload, but only when Hermes processes untrusted JavaScript, meaning most React Native applications are unaffected. With a CVSS score of 9.8 (Critical), it presents a severe risk with network-based exploitation, low attack complexity, and high impact on confidentiality, integrity, and availability. Despite its critical severity, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:facebook:hermes:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.